Where
-Infinity
0
Severity
6.9
AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/AU:N/R:A/V:D/RE:M/U:Amber

An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for disabling, disconnecting, or uninstalling the GlobalProtect app. After the passcode is known, the user can perform these actions even if the GlobalProtect app configuration would not normally permit them to do so.

First published (updated )
Severity
7.7
Buffer Overflow
AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber

A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man in the middle attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges. This vulnerability is triggered during the processing of requests and responses exchanged between Portal and Gateway.

The GlobalProtect app on iOS is not affected.

1 / 2
Source: MITRE
First published (updated )
Severity
8.4
AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H/E:U/AU:N/R:U/V:D/RE:M/U:Amber

An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on enables a locally authenticated non administrative user to escalate their privileges to root on macOS and Linux or NT AUTHORITY\SYSTEM on Windows.

The GlobalProtect app on iOS, Android, Chrome OS and GlobalProtect UWP app are not affected.

Remedy

No workaround or mitigation is available.

Remedy

VERSION MINOR VERSION SUGGESTED SOLUTION GlobalProtect App 6.3 on macOS 6.3.0 through 6.3.3 Upgrade to 6.3.3-h1 (6.3.3-c650) or later. GlobalProtect App 6.3 on Windows 6.3.0 through 6.3.3 Upgrade to 6.3.3-h1 (6.3.3-c650) or later. GlobalProtect App 6.2 on macOS 6.2.0 through 6.2.8 Upgrade to 6.2.8-h2 (6.2.8-c243) or later. GlobalProtect App 6.2 on Windows 6.2.0 through 6.2.8 Upgrade to 6.2.8-h2 (6.2.8-c243) or later. GlobalProtect App 6.1 on macOS Upgrade to 6.2.8-h2 (6.2.8-c243) or 6.3.3-h1 (6.3.3-c650) or later. GlobalProtect App 6.1 on Windows Upgrade to 6.2.8-h2 (6.2.8-c243) or 6.3.3-h1 (6.3.3-c650) or later. GlobalProtect App 6.0 on macOS Upgrade to 6.2.8-h2 (6.2.8-c243) or 6.3.3-h1 (6.3.3-c650) or later. GlobalProtect App 6.0 on Windows Upgrade to 6.2.8-h2 (6.2.8-c243) or 6.3.3-h1 (6.3.3-c650) or later. GlobalProtect App 6.2 on Linux 6.2.0 through 6.2.7 Upgrade to 6.2.8 or later. GlobalProtect App 6.1 on Linux Upgrade to 6.2.8 or later. GlobalProtect App 6.0 on Linux Upgrade to 6.2.8 or later. GlobalProtect App on Android, Chrome OS, iOS   No action needed. GlobalProtect UWP App No action needed.
First published (updated )
Severity
8
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:L/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber

A vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a remote attacker to run ActiveX controls within the context of an authenticated Windows user. This enables the attacker to run commands as if they are a legitimate authenticated user. However, to exploit this vulnerability, the authenticated user must navigate to a malicious page during the GlobalProtect SAML login process on a Windows device.

This issue does not apply to the GlobalProtect app on other (non-Windows) platforms.

First published (updated )
Severity
7.1
AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H/E:U/AU:N/R:U/V:D/RE:M/U:Amber

A reliance on untrusted input for a security decision in the GlobalProtect app on Windows devices potentially enables a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM.

GlobalProtect App on Linux, iOS, Android, Chrome OS and GlobalProtect UWP App are not affected.

1 / 2
Source: MITRE

Remedy

No workaround or mitigation is available.

Remedy

VERSION SUGGESTED SOLUTION GlobalProtect App 6.3 on Windows Upgrade to 6.3.3 or later* GlobalProtect App 6.2 on Windows Upgrade to 6.2.6 or later* GlobalProtect App 6.1 on Windows Upgrade to 6.2.6 or later or upgrade to 6.3.3 or later* GlobalProtect App 6.0 on Windows Upgrade to 6.0.12 or later or upgrade to 6.2.6 or later or upgrade to 6.3.3 or later* GlobalProtect App on Linux No action needed GlobalProtect App on macOS No action needed GlobalProtect App on iOS No action needed GlobalProtect App on Android No action needed GlobalProtect UWP App No action needed * In addition to the software updates listed above, additional steps are required to protect against this vulnerability as described below. ** These steps are not needed for GlobalProtect app 6.2.8-h3 (6.2.8-c263) and later versions of GlobalProtect 6.2. Solution for new and existing GlobalProtect app installation on Windows You can use your endpoint mobile device management (MDM) tools to apply the following changes: 1. Install a fixed version of the GlobalProtect app. 2. Update the following registry key with the specified value (uses the REG_SZ type): [HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto Networks\GlobalProtect\Settings] "check-communication"="yes" 3. Restart the operating system to apply this registry change. Alternate solution for new GlobalProtect app installation on Windows Install the GlobalProtect app with the pre-deployment key CHECKCOMM set to "yes": > msiexec.exe /i GlobalProtect64.msi CHECKCOMM="yes" Note: This command adds the registry value from the previous solution instructions—no additional MSI options are needed.
First published (updated )
Severity
7
Race Condition
AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race condition.

Remedy

This issue is fixed in GlobalProtect app 5.1.12, GlobalProtect app 6.0.8, GlobalProtect app 6.1.2, GlobalProtect app 6.2.1, and all later GlobalProtect app versions on Windows.
First published (updated )
Severity
5.5
AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

An issue in the Palo Alto Networks GlobalProtect app enables a non-privileged user to disable the GlobalProtect app in configurations that allow a user to disable GlobalProtect with a passcode.

Remedy

This issue is fixed in GlobalProtect app 5.1.12, GlobalProtect app 5.2.13, GlobalProtect app 6.0.4, GlobalProtect app 6.1.1, and all later GlobalProtect app versions.
First published (updated )
EOL
Dec 31, 2025
Support Ends
Mar 1, 2025

End of life: 12/31/2025, End of support: 3/1/2025, Latest version: 6.1.5

First published (updated )
EOL
Dec 31, 2025
Support Ends
Mar 1, 2025

End of life: 12/31/2025, End of support: 3/1/2025, Latest version: 6.1.5

First published (updated )
EOL
Dec 31, 2024
Support Ends
Mar 12, 2021

End of life: 12/31/2024, End of support: 3/12/2021, Latest version: 5.1.12

First published (updated )
EOL
Dec 31, 2024
Support Ends
Mar 12, 2021

End of life: 12/31/2024, End of support: 3/12/2021, Latest version: 5.1.12

First published (updated )
EOL
Jan 30, 2019
Support Ends
May 2, 2018

End of life: 1/30/2019, End of support: 5/2/2018, Latest version: 4.0

First published (updated )
EOL
Jan 30, 2019
Support Ends
May 2, 2018

End of life: 1/30/2019, End of support: 5/2/2018, Latest version: 4.0

First published (updated )
EOL
Jun 23, 2018
Support Ends
Sep 23, 2017

End of life: 6/23/2018, End of support: 9/23/2017, Latest version: 3.1

First published (updated )
EOL
Jun 23, 2018
Support Ends
Sep 23, 2017

End of life: 6/23/2018, End of support: 9/23/2017, Latest version: 3.1

First published (updated )
EOL
Feb 15, 2018
Support Ends
May 18, 2017

End of life: 2/15/2018, End of support: 5/18/2017, Latest version: 3.0

First published (updated )
EOL
Feb 15, 2018
Support Ends
May 18, 2017

End of life: 2/15/2018, End of support: 5/18/2017, Latest version: 3.0

First published (updated )
Severity
5.8
AV:N/AC:M/Au:N/C:P/I:P/A:N

Palo Alto Networks GlobalProtect before 1.1.7, and NetConnect, does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof portal servers and obtain sensitive information via a crafted certificate.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203